CVE-2026-72550 is an SQL injection vulnerability affecting Friendica through the 2026.08-dev branch. The flaw is reachable via the photo-view order parameter, which is concatenated without escaping into a SHOW COLUMNS SQL query and executed through a bare PDO::query() call. Because attacker-controlled input is incorporated directly into the query, unauthenticated remote attackers can perform stacked statement injection and execute arbitrary SQL statements against the backend database. The vulnerability can expose the full contents of the application database and permits unauthorized modification or deletion of stored data.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small standalone Python proof-of-concept exploit for CVE-2026-72550, an unauthenticated stacked-query SQL injection in Friendica’s photo-view endpoint. The repo contains three files: README.md with vulnerability details and usage examples, exploit.py implementing the attack logic, and requirements.txt listing the requests dependency. The exploit targets Friendica instances by constructing requests to /photos/<user>/image/<resource-id> and injecting SQL through the order query parameter. The script first performs a control request using order=created, then sends a timing payload built as x';SELECT SLEEP(n)-- - to determine whether stacked SQL execution is possible. If the response delay exceeds a threshold, the target is considered vulnerable. After confirmation, the script supports blind time-based extraction of selected values using IF(...,SLEEP(n),0) conditions. It includes predefined extraction expressions for @@version, USER(), DATABASE(), and the first admin email from the user table. Length extraction is done with a binary search over LENGTH(expression), and character extraction iterates through a hardcoded charset using SUBSTRING(expression,pos,1) comparisons. Main capabilities: unauthenticated vulnerability verification, timing-based blind SQLi exfiltration, and practical demonstration of arbitrary SQL execution potential. Although the README notes the vulnerability could allow arbitrary INSERT/UPDATE/DELETE and admin creation, the provided code itself does not automate writes or privilege escalation; it is focused on detection plus limited data extraction. Overall, this is a real exploit script rather than a mere detector, but it remains a basic operational PoC: payloads are hardcoded around timing-based SQLi and extraction targets are limited to a few predefined database expressions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.